Fortinet Blog | News and Threat Research

  • Products
  • Solutions
  • Service & Support
  • Partners
  • Corporate
  • Resources
  • How to Buy

Mobile Botnets: We Had Told You So

by RSS Axelle Apvrille  |  April 20, 2012  |  Category: Security Research

Mobile botnet Android/RootSmart (aka Bmaster) is making substantial amount of money from premium SMS numbers or services, according to Cathal Mullaney’s discovery of a mobile botnet front-end: yes, we had told you so.

Glance at Guillaume Lovet’s paper at Virus Bulletin back in 2006, where he explains the business behind mobile botnets. His illustration is exactly what Android/RootSmart (aka Bmaster) does:

Later, atSAR SSI in 2010, I re-insisted on the potential impact of such strategies:

It’s interesting to notice my estimate of 20,000 SMS turns out to be accurate… per day: Android/RootSmart shows between 10,000 and 30,000 active devices each day.

I had also told you several times about the dangers of SMS short codes or premium numbers (1, 2, 3, 4, 5). With over 50% of mobile malware families sending SMS messages, I believe Trojan dialers are our ennemy #1 - along with focused spyware like Zitmo and Spitmo. Technically speaking, too, I am not surprised mobile botmasters control their bots via Internet: it’s easy to monitor and C&C can be relocated if necessary. PoCs like Georgia Weidman’s where commands are sent via SMS do not seem very scalable to me (problems to send & process the SMS without raising suspiciousness). It looks like the architecture SymbOS/Yxes drafted 2.5 years ago wins: that’s exactly what Android/RootSmart re-uses (apart from the automated propagation step which is not included). So, really, we had warned you. But I don’t mind repeating myself: I am a mother ;)

By the way, if you are still listening: another warning for you. I foresee mobile botnets will try and spread via social networks. – the Crypto Girl

by RSS Axelle Apvrille  |  April 20, 2012  |  Category: Security Research
Tags: botnet mobile premium sms
comments powered by Disqus

Category

  • All
  • RSS Subscribe
  • Security Research
  • RSS Subscribe
  • Industry Trends & News
  • RSS Subscribe

FortiGuard Labs on the Web

  • Twitter Twitter
  • Facebook Facebook
  • LinkedIn LinkedIn
  • Youtube Youtube

Monthly Archives

  • May 2013 8
  • April 2013 17
  • March 2013 12
  • February 2013 11
  • January 2013 12
  • December 2012 8
  • November 2012 7
  • October 2012 4
  • September 2012 7
  • August 2012 7
  • July 2012 9
  • June 2012 17
  • May 2012 14
  • April 2012 16
  • March 2012 15
  • February 2012 11
  • January 2012 6
  • December 2011 4
  • November 2011 6
  • October 2011 11
  • September 2011 2
  • August 2011 2
  • July 2011 4
  • June 2011 6
  • May 2011 6
  • April 2011 5
  • March 2011 7
  • February 2011 5
  • January 2011 7
  • December 2010 8
  • November 2010 11
  • October 2010 3
  • September 2010 8
  • August 2010 4
  • July 2010 9
  • June 2010 9
  • May 2010 9
  • April 2010 6
  • March 2010 8
  • February 2010 6
  • January 2010 9
  • December 2009 8
  • November 2009 6
  • October 2009 6
  • September 2009 8
  • August 2009 5
  • July 2009 8
  • June 2009 7
  • May 2009 4
  • April 2009 7
  • March 2009 9
  • February 2009 4
  • January 2009 1
  • Older

Popular topics

mobile malware sms Antivirus mobile phones conference hashdays UTM Threat Landscape reverse engineering bredolab trojan Windows Anti-Spam google Malware Anonymous webinar symbos/yxes reversing virut facebook stuxnet mobile phone Cryptography Security Zeus challenge Firewall iphone apple Research derek manky Fortinet FortiGate mobile symbianos privacy android BYOD zitmo exploit Mac OS X microsoft adobe botnet SpyEye symbian Mobile Security hacking challenge network security